Law · Privacy · California
CCPA CPRA compliance means meeting the California Consumer Privacy Act as amended by the California Privacy Rights Act, enforced by the CPPA and the Attorney General. New CPPA regulations took effect on 1 January 2026, adding privacy risk assessments, rules for automated decision-making and annual cybersecurity audits from 2028.
For-profit businesses doing business in California that meet one of the thresholds.
QULDEX helps here first: the readiness check shows where you stand before you commit budget.
The CCPA requires covered businesses to give notice at collection, honour rights to know, delete, correct, opt out and limit, keep contracts with service providers, maintain reasonable security and, under the 2026 regulations, assess risk, audit cybersecurity and govern ADMT.
What, why and how long.
In QULDEX: Notice versionsKnow, delete, correct, opt out, limit.
In QULDEX: Request log with deadlinesIncluding Global Privacy Control.
In QULDEX: Signal testsSignificant-risk processing.
In QULDEX: Assessment workflowFrom 2028 by revenue.
In QULDEX: Audit workspaceBreach lawsuits if not.
In QULDEX: Security evidenceThese 15 sections and regulations carry the obligations most businesses work on. Select any one to see what it requires, typical evidence and the matching GDPR or security reference.
Showing up to 6 per group. Search, filter, or open a group to see all 15.
1798.140(d)Who is a businessFor-profit entities doing business in California that meet a revenue threshold (adjusted for inflation), buy, sell or share data of 100,000+ consumers or households, or earn half their revenue from selling or sharing personal information.
In QULDEXThresholds are recorded with the figures used.
1798.140(v)Personal and sensitive personal informationPersonal information is broad; sensitive personal information includes government IDs, precise geolocation, health, biometrics and account log-ins.
In QULDEXSensitive data is tagged in the data map.
1798.100Right to know and notice at collectionTell consumers at or before collection what you collect, why and for how long.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
1798.105Right to deleteDelete personal information on request, with listed exceptions, and tell service providers to delete too.
In QULDEXRequests are logged with 45-day deadlines.
1798.106Right to correctCorrect inaccurate personal information on request.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
1798.120Right to opt out of sale or sharingOffer "Do Not Sell or Share My Personal Information" and honour opt-out preference signals such as Global Privacy Control.
In QULDEXOpt-out signals are tested as a control.
1798.121Right to limit sensitive data useLet consumers limit the use of sensitive personal information.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
1798.125No discriminationDo not discriminate against consumers for exercising their rights.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Cyber auditAnnual cybersecurity auditsNew in 2026 regulationsBusinesses whose processing presents significant risk complete independent cybersecurity audits; first certifications are due from 1 April 2028 to 2030, by revenue.
In QULDEXAudit scope and evidence sit in the audit workspace.
Risk assessmentPrivacy risk assessmentsNew in 2026 regulationsAssess processing that presents significant risk, such as selling or sharing data or processing sensitive data; compliance from 1 January 2026, submissions from April 2028.
In QULDEXRisk assessments run with sign-off and submission records.
ADMTAutomated decision-making technologyNew in 2026 regulationsNotice, opt-out and access rights where ADMT is used for significant decisions, from 2027.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
1798.100(d)Contracts with service providers and contractorsContracts must limit use of personal information and require compliance.
In QULDEXEach service provider is linked to its contract terms.
1798.100(e)Reasonable securityImplement reasonable security procedures and practices appropriate to the data.
In QULDEXSecurity controls are reused from ISO 27001 or SOC 2.
1798.150Private right of action for breachesConsumers can sue for data breaches caused by a failure to maintain reasonable security.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
1798.155Administrative finesFines per violation, higher for intentional violations or those involving minors, adjusted for inflation; enforced by the CPPA and the Attorney General.
In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.
Nothing matches that search.
Section numbers follow the California Civil Code; regulation summaries follow the CPPA regulations approved in September 2025. Summaries are QULDEX paraphrases, not legal advice.
Confirm you are covered, map personal and sensitive data, fix notices and rights handling, then add risk assessments now and prepare for audits and ADMT rules. Most businesses need 3 to 6 months for the core and plan the audit work into 2027.
Revenue, data volume and selling or sharing share.
Sources, purposes, retention, sharing and service providers.
Notice at collection, request handling and Global Privacy Control.
Assess significant-risk processing from 1 January 2026.
Scope, evidence and an independent auditor before your due date.
Dates follow the CPPA regulations approved in September 2025. Durations are QULDEX planning ranges.
The CPPA and auditors will ask for these.
| Record | Section | Where it lives in QULDEX |
|---|---|---|
| Applicability assessment | 1798.140(d) | Risk register |
| Data map with sensitive data | 1798.140(v) | Risk register |
| Notice at collection and privacy policy | 1798.100 | Policy library |
| Consumer request log | 1798.105–1798.121 | Evidence vault |
| Opt-out signal test evidence | 1798.120 | Evidence vault |
| Service provider contracts | 1798.100(d) | Vendor register |
| Privacy risk assessments | 2026 regulations | Audit workspace |
| Cybersecurity audit report and certification | 2026 regulations | Audit workspace |
Record names are QULDEX recommendations.
The core programme typically takes 3 to 6 months; the cybersecurity audit adds 3 to 6 months of preparation before its due date. Data selling or sharing, sensitive data and ad-tech drive the effort.
Bars show the upper end of each range on one scale (6 months = full width).
Check these eight things first. Nothing you enter leaves this page.
The CCPA is opt-out based where GDPR is consent based, but rights handling, risk assessments and security evidence overlap heavily.
| CCPA / CPRA | GDPR | |
|---|---|---|
| Model | Notice and opt-out (opt-in for minors) | Lawful basis, often consent |
| Scope | Businesses meeting thresholds | Any controller or processor in scope |
| Assessments | Risk assessments under 2026 regulations | DPIAs for high risk |
| Security audits | Independent cybersecurity audits from 2028 | No audit mandate |
| Enforcement | CPPA, Attorney General, private action for breaches | Supervisory authorities |
| In QULDEX | QULDEX maps each process to both laws, so one privacy programme serves California and the EU. | |
| CCPA / CPRA | GDPR | ISO 27701:2025 | SOC 2 | Shared evidence |
|---|---|---|---|---|
| 1798.100 Notice | Art. 13–14 | Notices | P1 | Notices |
| 1798.105 Delete | Art. 17 | Erasure | P4 | Request log |
| 1798.120 Opt-out | Art. 21 | Objection | P2 | Opt-out evidence |
| 1798.100(d) Contracts | Art. 28 | Processor contracts | CC9.2 | Contracts |
| Reasonable security | Art. 32 | Security for PII | CC6–CC8 | Security evidence |
| Risk assessments | Art. 35 | Impact assessment | CC3.2 | Assessments |
| Cybersecurity audit | — | — | SOC 2 report | Audit report |
Indicative mapping for planning, not legal advice.
QULDEX is CCPA compliance and audit management software built from EGV Group's audit delivery, used by businesses, their privacy teams and the independent cybersecurity auditors the 2026 regulations require. Pick your role to see who does what.
For businesses meeting the CCPA thresholds.
For privacy consultants and internal audit.
For independent auditors under the 2026 regulations.
Requirements with owners, test steps and the crosswalk to 50+ frameworks.
Explore →EvidenceEvidence linked to controls and findings, with upload, review and approval history.
Explore →RiskRisk assessment and treatment, with decisions traced to the controls they drive.
Explore →FindingsFindings from internal and external audits tracked to closure with due dates.
Explore →For-profit businesses doing business in California that exceed the inflation-adjusted revenue threshold, buy, sell or share personal information of 100,000 or more consumers or households, or earn at least half their revenue from selling or sharing personal information.
Regulations approved in September 2025 and effective 1 January 2026 add privacy risk assessments, rules for automated decision-making technology (from 2027) and annual cybersecurity audits (certifications from 2028).
Certifications are due by 1 April 2028 for businesses with over $100 million in revenue, 1 April 2029 for $50–100 million, and 1 April 2030 for those under $50 million.
Administrative fines per violation, higher for intentional violations or those involving minors, adjusted for inflation each year, plus statutory damages in consumer lawsuits after certain data breaches.
To know, delete and correct their personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for using these rights.
GDPR, ISO 27701 and privacy-law comparisons.
blog.quldex.comA file-naming scheme auditors can follow.
blog.quldex.comHow many samples auditors look at.
blog.quldex.comSecurity reports that support a cybersecurity audit.
Reviewed by
Answer a short readiness check and get a gap summary by area. No sales call needed to see the result.